Warning: ini_set(): Session ini settings cannot be changed when a session is active in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 12

Warning: Trying to access array offset on value of type null in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1071

Warning: Trying to access array offset on value of type null in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1072

Warning: Undefined array key 1 in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1105

Warning: Undefined array key 2 in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1105

Warning: Undefined array key 3 in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1105

Warning: Undefined array key 4 in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1105

Warning: Undefined array key 5 in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1105

Warning: Undefined variable $link_subfolder1 in /home/u319666691/domains/cybersecurityboard.com/public_html/index.php on line 1134

Warning: Undefined variable $meta_article in /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php on line 100

Warning: Undefined variable $meta_og in /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php on line 100

Warning: Undefined variable $meta_twitter in /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php on line 100

Warning: Undefined variable $login_loggedon_html in /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php on line 142
SAP's First Patches of 2024 Resolve Critical Vulnerabilities | CyberSecurityBoard

Warning: Undefined variable $comments_html in /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php on line 527

SAP's First Patches of 2024 Resolve Critical Vulnerabilities

Enterprise software maker SAP this week announced the release of 10 new and two updated security notes as part of its first Security Patch Day of 2024.
Rated 'hot news', the highest rating in SAP's notebook, two of the new and one of the updated security notes deal with critical-severity escalation of privilege vulnerabilities in several products, SAP explains in its advisory.
The first hot news security note resolves CVE-2023-49583, a security defect in Business Application Studio, Web IDE Full-Stack and Web IDE for SAP HANA. The issue impacts SAP customers who created Node.js applications using the aforementioned SAP software, as these applications may rely on dependencies that use vulnerable versions of two SAP libraries, enterprise software security firm Onapsis explains.
SAP's second hot news note addresses the same vulnerability, along with CVE-2023-50422, in Edge Integration Cell, a hybrid solution that comes with SAP Integration Suite to provide API integration and which relies on BTP Security Services Integration Libraries and Programming Infrastructures, Onapsis explains.
The third hot news security note is an update to a note released in December 2023 to resolve multiple escalation of privilege bugs in Business Technology Platform Security Services Integration Libraries, including CVE-2023-49583 and CVE-2023-50422.
SAP also resolved four high-severity vulnerabilities on its first Security Patch Day of 2024.
The first is a code injection bug in Application Interface Framework that could allow an attacker to execute OS commands.
The second high-severity flaw is described as a denial-of-service issue in Web Dispatcher and NetWeaver Application Server ABAP that could be exploited without authentication.
Next in line is an information disclosure defect in the Microsoft Edge browser extension, while the fourth high-severity bug is an improper authorization check in LT Replication Server.
The five remaining security notes deal with four medium- and one low-severity vulnerability in S/4HANA Finance, NetWeaver AS for Java, NetWeaver ABAP Application Server and ABAP Platform, NetWeaver Internet Communication Manage, and Marketing.
SAP customers are advised to apply the patches as soon as possible.
While the software maker makes no mention of any of these vulnerabilities being exploited in the wild, unpatched SAP applications are known to have been exploited in malicious attacks.


This Cyber News was published on www.securityweek.com. Publication date: Wed, 10 Jan 2024 13:43:05 +0000


Cyber News related to SAP's First Patches of 2024 Resolve Critical Vulnerabilities


Fatal error: Uncaught mysqli_sql_exception: You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near 's First Patches of 2024 Resolve Critical Vulnerabilities') AS score FROM TPL_...' at line 1 in /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php:336 Stack trace: #0 /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php(336): mysqli_query() #1 /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php(548): template_block() #2 /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php(531): template_related() #3 /home/u319666691/domains/cybersecurityboard.com/public_html/index.php(1135): template_content() #4 {main} thrown in /home/u319666691/domains/cybersecurityboard.com/public_html/_template.php on line 336